We have a pair of 1101E's in HA (A-P) currently in production. They are connected to Meraki MS450's.
We purchased some fortiswitches that we want to manage in the gate via fortilink, but we did not enable fortilink on our 40gbps LAG configuration before adding subinterfaces, policies, etc. So we are now unable to configure fortilink on this interface.
We talked to support and they recommended that we take a backup of the current config, add "set fortilink enable" to our LAG in the config file, and then restore the gates from the modified config file.
Does anyone have experience doing anything like this?
The fortiswitches will not be diretly connected to the gate, they will be downstream and connected to MS225's/MS425's. Our gate is currently on 7.0.13.
Thanks!
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi @cgwv,
Have you tried to enable fortilink on the LAG interface? If yes, did you get any error messages? I tested in my lab. I have an 802.3ad Aggregate interface with a VLAN subinterface and a firewall policy for that VLAN. I was able to enable fortilink for that 802.3ad Aggregate interface in the CLI without any issues.
config system interface
edit LAG
set fortilink enable
end
Regards,
Hi @cgwv,
Have you tried to enable fortilink on the LAG interface? If yes, did you get any error messages? I tested in my lab. I have an 802.3ad Aggregate interface with a VLAN subinterface and a firewall policy for that VLAN. I was able to enable fortilink for that 802.3ad Aggregate interface in the CLI without any issues.
config system interface
edit LAG
set fortilink enable
end
Regards,
Hey, @hbac,
So we tried to add it through the GUI. No error message, the LAG just doesnt show up in the list of interfaces that we can choose from to add as a fortlink interface.
When we talked to support, they told us that if we did what you just suggested that it would wipe out the rest of the configuration on the LAG interface. So we did not try that lol.
We have a 61F we can test it on, so we'll try it out. Thanks!
Adding FortiLink to an existing LAG involves modifying the configuration by enabling FortiLink on the LAG interface. Support suggests a backup, adding "set fortilink enable" to the config, then restoring. Experience with this process can ensure a smooth transition. The FortiSwitches, downstream from MS225's/MS425's, will benefit from improved management via FortiLink. Ensure compatibility with the current gate version (7.0.13). Drift Boss
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1105 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.